Slashdot Mirror


Popular WordPress Plugin WPML Hacked By Angry Former Employee (zdnet.com)

A very popular WordPress plugin was hacked over the weekend after a hacker defaced its website and sent a mass message to all its customers revealing the existence of supposed unpatched security holes. From a report: In a follow-up mass email, the plugin's developers blamed the hack on a former employee, who also defaced their website. The plugin in question is WPML (or WP MultiLingual), the most popular WordPress plugin for translating and serving WordPress sites in multiple languages. According to its website, WPML has over 600,000 paying customers and is one of the very few WordPress plugins that is so reputable that it doesn't need to advertise itself with a free version on the official WordPress.org plugins repository. But on Saturday, ET timezone, the plugin faced its first major security incident since its launch in 2007. The attacker, which the WPML team claims is a former employee, sent out a mass email to all the plugin's customers.

3 of 37 comments (clear)

  1. Security by Anonymous Coward · · Score: 0, Insightful

    If your security is so shitty that a *former* employee can deface your website, you basically don't have any security...

    1. Re:Security by Anonymous Coward · · Score: 0, Insightful

      Because PHP is still a fractal of bad design.

  2. Enjoy your criminal record, idiot by bigmacx · · Score: 5, Insightful

    Hope they get this idiot charged and release their name.

    Every time one of these "inside" IT type persons does something against an employer by using their privileged access to their systems, it makes it more difficult for all of us to operate within our own companies. And don't try to fault me by the "ex-employee" logic. Any one of us knows full well we could fsck with a former employer's systems even if they think they've locked us out.

    Those in our field that violate the trust placed in us by employers should be drawn and quartered, tarred and feathered. At they very least named and shamed.